cs-backend-review
Backend engineering review — walks the 7 Matt Pocock forcing questions (read/write ratio + QPS, tenancy, sync vs async, data sensitivity, pattern, RPO/RTO,…
A command is the one you type. It runs exactly when you ask it to, and never before.
8,051 commands across 583 plugins.
Backend engineering review — walks the 7 Matt Pocock forcing questions (read/write ratio + QPS, tenancy, sync vs async, data sensitivity, pattern, RPO/RTO,…
Generate comprehensive PR descriptions following repository templates
Generate comprehensive PR descriptions following repository templates
Create Linear ticket and PR for experimental features after implementation
Execute a Jira ticket following its implementation plan
Reference for: Common Ground Load when: Storage operations, project identification, file format
Reference for: Common Ground Load when: Using --graph flag, generating mermaid diagrams
Spawn a worker agent session in a registered project. The session runs the chosen agent in a fresh git worktree. Register the project first with `ao project…
Fetch (if needed) and open the Agent Orchestrator desktop app. The desktop app owns the daemon, state, and updates. `ao start` no longer runs a daemon: it…
Show AO daemon status. Use this to verify the daemon is up and check which port it is bound to.
Layered regression stability gate: capture baseline behavior on the base ref, diff the candidate, verdict STABLE/UNSTABLE before you push
Generate edge cases across 12 dimensions from a seed scenario
Comprehensive security and quality review of uncommitted changes:
Commit changes following Conventional Commits format (local only, no push).
Search the Repowise wiki using natural language, full-text, or symbol search.
Check the health of your Repowise index — sync state, page counts, provider, and token usage.
Trigger an incremental Repowise update to sync documentation with recent code changes.
On-demand intelligence fetch for a target — CVEs, disclosed reports, new features. Wraps learn.py + hunt memory context. Usage: /intel target.com
JWT attack toolkit (offline) — alg:none forgery, RS256→HS256 algorithm confusion, weak-secret crack, static claim analysis. Usage: /jwt-scan <token>…
LLM red-team corpus runner — fires categorized prompt-injection / jailbreak / system-prompt-leak / data-exfil / indirect-injection / guardrail-bypass payloads…
Review and process everything captured on the go from the Telegram journal bot - voice, text, images, PDFs, links - waiting in the catchup queue. You pull it…
Red-team your current idea against your own vault history - finds contradictions, past failures, and flawed assumptions
Bridge two unrelated domains using your vault's link graph - forces creative friction to spark new ideas
Mandatory pre-flight scope check — verify an asset is in scope BEFORE any HTTP touch. Deterministic (deny-wins, default-deny) via engine/scope.py against the…
Show ranked attack surface for a target from its recon manifest + hunt memory. Deterministic backing is `cbh surface <target>` (reads…
Meme coin and token security scan — checks for rug pull vectors (hidden mint, honeypot, fee manipulation, LP lock bypass, authority retention, bonding curve…
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic